Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 561

nvd логотип

CVE-2020-15670

почти 6 лет назад

Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-15670

почти 6 лет назад

Mozilla developers reported memory safety bugs present in Firefox for ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-15668

почти 6 лет назад

A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-15668

почти 6 лет назад

A lock was missing when accessing a data structure and importing certi ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-15667

почти 6 лет назад

When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released by Mozilla, this issue is only exploitable with the Mozilla-controlled signing key. This vulnerability affects Firefox < 80.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-15667

почти 6 лет назад

When processing a MAR update file, after the signature has been valida ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-15666

почти 6 лет назад

When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-15666

почти 6 лет назад

When trying to load a non-video in an audio/video context the exact st ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2020-15665

почти 6 лет назад

Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. This could have resulted in an incorrect URL being shown when used in conjunction with other unexpected browser behaviors. This vulnerability affects Firefox < 80.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-15665

почти 6 лет назад

Firefox did not reset the address bar after the beforeunload dialog wa ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-15670

Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80.

CVSS3: 8.8
1%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-15670

Mozilla developers reported memory safety bugs present in Firefox for ...

CVSS3: 8.8
1%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-15668

A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.3
1%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-15668

A lock was missing when accessing a data structure and importing certi ...

CVSS3: 4.3
1%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-15667

When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released by Mozilla, this issue is only exploitable with the Mozilla-controlled signing key. This vulnerability affects Firefox < 80.

CVSS3: 8.8
2%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-15667

When processing a MAR update file, after the signature has been valida ...

CVSS3: 8.8
2%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-15666

When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 6.5
1%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-15666

When trying to load a non-video in an audio/video context the exact st ...

CVSS3: 6.5
1%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-15665

Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. This could have resulted in an incorrect URL being shown when used in conjunction with other unexpected browser behaviors. This vulnerability affects Firefox < 80.

CVSS3: 4.3
1%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-15665

Firefox did not reset the address bar after the beforeunload dialog wa ...

CVSS3: 4.3
1%
Низкий
почти 6 лет назад

Уязвимостей на страницу


Поделиться